Example: quiz answers

Information Security and ISO27001 – an Introduction

Information Security and ISO27001 an Introduction Overview What is ISO 27001 (BS7799), and how does this standard help organizations more effectively manage their Information Security ? What's the relationship between ISO 27001 (BS7799) and ISO 17799, how can it relate to ISO 9001, and what does someone coming to this field for the first time need to know in order to initiate, or take on responsibility for, an organizational Information Security project, and specifically one that is intended to lead to ISO 27001 (BS7799) certification? This paper, written by the ISO 27001/BS7799 expert Alan Calder, answers these basic questions and others and points to online resources and tools that are useful to anyone tasked with leading an Information Security project.

Information Security and ISO27001 – an Introduction Overview What is ISO 27001 (BS7799), and how does this standard help organizations more effectively

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Information Security and ISO27001 – an Introduction

1 Information Security and ISO27001 an Introduction Overview What is ISO 27001 (BS7799), and how does this standard help organizations more effectively manage their Information Security ? What's the relationship between ISO 27001 (BS7799) and ISO 17799, how can it relate to ISO 9001, and what does someone coming to this field for the first time need to know in order to initiate, or take on responsibility for, an organizational Information Security project, and specifically one that is intended to lead to ISO 27001 (BS7799) certification? This paper, written by the ISO 27001/BS7799 expert Alan Calder, answers these basic questions and others and points to online resources and tools that are useful to anyone tasked with leading an Information Security project.

2 The Information in this paper is suitable for all sizes of organizations, and all sectors, anywhere in the world. It reflects the guidance and Information available from The ISO27001 Site, which can be accessed through IT Governance and Information Security The last few years have seen board corporate governance requirements increasingly more defined and specific. As Information technology has become pervasive, underpinning and supporting almost every aspect of the organization, manipulating and storing the Information on which the organization depends for its survival, so the role of IT in corporate governance has become more clearly defined and IT governance is increasingly recognised as a specific area for board and corporate attention.

3 A fundamental aspect of IT governance is the protection of the Information its availability, confidentiality and integrity on which everything else depends. In parallel, international standards related to Information Security have emerged and have become one of the cornerstones of an effective IT governance framework. The Information Security standards BS7799 was created in 1995, by the British Standards Institution (BSI), as a standard to guide the development and implementation of an Information Security Management System, commonly known as an ISMS. BS7799 was conceived, from the outset, as a technology-neutral, vendor-neutral management system that, properly implemented, would enable an organization's management to assure itself that its Information Security measures and arrangements were effective.

4 From the outset, BS7799 focused on protecting the availability, confidentiality and integrity of organizational Information and this remains, today, the driving objective of the standard. Crucially though, it doesn't talk about protection from every single possible threat, but only from those that the organization considers relevant and only to the extent that is justified financially and commercially through a risk assessment. BS7799 was originally just a single standard, and had the status of a Code of Practice. In other words, it provided guidance for organizations, but hadn't been written as specification ( ) Copyright IT Governance Ltd 2005, 2006 Page 1 of 6 Information Security and ISO27001 an Introduction that could form the basis of an external third party verification and certification scheme.

5 As more and more organizations began to recognize the scale, severity and interconnectedness of Information Security threats, and with the emergence of a growing range of data protection and privacy-related law and regulation, so the demand for a certification option linked to the standard began to develop. This led, eventually, to the emergence of a second part to the standard, in the form of a specification (a specification uses words like shall ) numbered as BS7799-2 (or, part 2). The Code of Practice (which uses words like may and which deals with controls, not with Information Security Management Systems), is now recognized under the dual numbers of ISO17799 and BS7799-1 (or, part 1).

6 The relationship between the Code of Practice and the specification was also established at this time: a specification is the basis for certification schemes and ISO 27001 mandates the use of ISO 17799 as the source of guidance for the selection and implementation of the controls mandated by ISO 27001. In effect, ISO 17799 is the second part of ISO 27001. The most recent version of the Code of Practice, and the one which must be used, is ISO/IEC 17799:2005. BS7799-2:2002 has also undergone revision and internationalisation, and was replaced in November 2005 by ISO/IEC 27001:2005. BS7799-2:2002 has now been withdrawn. The best way to keep in touch with the changes to the standards is to subscribe to 24743, the free Information Security newsletter that provides regularly updated FAQs on the new standards, as well as other ISMS Information .

7 Online subscription for 24743 is available here: The Information Security standards are the essential starting point for any organization that is commencing an Information Security project. Anyone contemplating such a project should purchase and study copies of both standards, which are available for online purchase in a money-saving kit, in either hard copy or electronic format, from here: Various countries have published their own versions of the British standards and they appear, for instance, as AS/NZS 7799. The international versions of these standards, which can be certified anywhere in the world, are likely to lead to the disappearance of local versions, other than on a dual-numbering basis.

8 It should also be noted that there are a number of sector-specific schemes, in which a specific industrial sector has developed its own version of BS7799 to reflect its specific concerns and issues. An example of this is the scheme developed in the UK by APACS. The Information Security and regulatory environments The two key reasons for the growing interest in certification to ISO 27001 are the proliferation of threats to Information and the growing range of regulatory and statutory requirements that relate to Information protection. Information Security threats are global in nature, and indiscriminately target every organization and individual who owns or uses (primarily) electronic Information .

9 These threats are automated and loose on the internet. In addition, data is exposed to many other dangers, from acts of nature, through external attack to internal corruption and theft. The last ten years have also seen the emergence of a growing body of legislation and regulation around Information and data Security , some aimed at ensuring that individual data is protected and some aimed at ensuring that corporate financial, operational and risk management systems are appropriately underpinned. A formal Information Security management system, that provides guidance for the deployment of best practice, is increasingly seen as a necessity in compliance terms and certification is increasingly required ( ) Copyright IT Governance Ltd 2005, 2006 Page 2 of 6 Information Security and ISO27001 an Introduction of organizations (and governments) before they will engage in any significant commercial transactions with potential new suppliers.

10 The implications of this for the outsourcing industry are self evident. The argument for deployment of a formal ISMS are fully developed in a short book called The Case for ISO 27001. This book, which is available online as an eBook from , (a soft cover version is also available) is also designed to provide a project manager with the arguments that may be necessary to get the organization's board to make the appropriate commitment to the project. Certification vs conformance It is possible for an organization to develop its ISMS in line with ISO17799 only, because the good practice identified in this Code of Practice is universally applicable. However, because it was not designed to be the basis of a certification scheme, it doesn't specify the system requirements with which an ISMS must be compliant if it is to be so certified.


Related search queries